Authenticated SQL Injection Vulnerability in OpenRemote by OpenRemote
CVE-2026-62238
7.2HIGH
What is CVE-2026-62238?
OpenRemote versions prior to 1.26.0 are susceptible to an authenticated SQL injection vulnerability within the datapoint crosstab export functionality. By leveraging this flaw, an attacker with asset creation or renaming privileges can manipulate SQL queries through the asset name input. This injection can lead to unauthorized data exposure, allowing the attacker to extract sensitive information from the database via the resultant CSV export.
Affected Version(s)
openremote 0 < 1.26.0
openremote 1.26.0
